Offensive Osint

Operational arsenal for authorized external red-team and bug-bounty recon. Concrete probes, wordlists, regexes, dorks, curl one-liners for: subdomain enum, GraphQL/Swagger/REST discovery, identity fabric (Entra/Okta/ADFS/Google/SAML/M365 deep — Teams/SharePoint/OneDrive), cloud bucket enum (S3/GCS/Azure), CDN/WAF bypass, origin discovery, vendor fingerprinting (Citrix/F5/Pulse/Fortinet/PaloAlto/Cisco/VMware), CI/CD exposure, 48-pattern secret-scan catalog, Postman workspaces, breach correlation, TLS/JA3 audit, secret triage. Detail content in 15 modular reference files. Use for any authorized recon: scoping, asset discovery, attack-path mapping, secret triage, severity scoring.

uphiago f1689ac 20 files · 256.4 KB Updated

File contents

uphiago/recon-skills/tree/main/redteam/offensive-osint commit f1689acfee

Frequently asked questions

npx skillmds@latest add uphiago/offensive-osint